Details
-
Task
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
Reviewed
Description
Doesn't look like this impacts us (we don't use SocketServer) however we should figure out what to do as the owasp checker is failing and the rating is quite high (9.8 - bound to get interest)
https://nvd.nist.gov/vuln/detail/CVE-2019-17571
Perhaps ZOOKEEPER-2342 should be prioritized.
Attachments
Issue Links
- is duplicated by
-
ZOOKEEPER-4305 log4j CVE problem
- Resolved
-
ZOOKEEPER-3990 Log4j 1.2.17 used by zookeeper 3.6.1 is vulnerable to CVE-2019-17571
- Resolved
- is fixed by
-
ZOOKEEPER-2342 Migrate to Log4J 2.
- Resolved
- links to